Reporting a security problem
We would rather hear about a problem from you than from a client. Last updated 18 September 2026.
Reporting
Email security@elementdigital.com.au. If you already deal with us through Arcio, security@arcio.au reaches the same people.
Please include:
- what the issue is, and what an attacker can achieve with it;
- the steps to reproduce it, or a proof of concept;
- the URL or system affected; and
- how you would like to be credited, if you would like to be.
If you need to send us something sensitive, say so and we will arrange an encrypted channel.
Please do not post it publicly before we have had a chance to fix it.
What is in scope
This website, and systems Element Digital runs for itself. That is what we are able to authorise you to test.
Our clients' systems are not in scope, and we cannot give you permission to test them. We are a consultancy: we build and run things that belong to other organisations, and an authorisation from us would not be worth anything if you tested one of them. If you believe you have found a problem affecting a client of ours, tell us and we will get it to the right people. Do not test it.
Reports that amount to a scanner's output with no demonstrated impact, missing headers on endpoints that hold nothing, or the absence of a feature you would have chosen differently, are welcome but will be triaged accordingly.
What we will do
| Stage | Target |
|---|---|
| Acknowledge your report | 2 business days |
| Initial assessment and severity | 5 business days |
| Fix or documented mitigation for a Critical or High issue | 30 days |
| Fix or documented mitigation for a Medium or Low issue | Next scheduled change |
We will keep you informed while we work, tell you when a fix ships, and credit you publicly unless you would rather we did not.
We do not run a paid bug bounty. We will acknowledge your work, and we are grateful for it.
Safe harbour
If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research. We consider that research authorised, and we will say so if a third party suggests otherwise.
Good faith means: you test only what is in scope above, you avoid privacy violations and destruction of data, you do not degrade anyone's service, you do not access or retain more data than you need to demonstrate the issue, and you give us reasonable time to fix the problem before disclosing it.
This safe harbour is ours to give for our own systems only. It does not extend to anyone else's, including our clients'.
This page
It is what /.well-known/security.txt points at, in the form RFC 9116 describes. It is published rather than kept internally because a safe harbour nobody can read protects nobody.